Documentation
¶
Overview ¶
Package alerting turns platform events a defender must act on into delivered notifications. It applies the tenant's alert rule, hands each qualifying alert to every configured sink, and audits the outcome per sink, so a missed page is visible in the audit log rather than silent. Delivery is best effort by design: the event that produced the alert (an incident, a finding) is already durable, and a failing webhook must never roll it back or block the pipeline that produced it.
Index ¶
- Variables
- type Outcome
- type Service
- func (s *Service) Close()
- func (s *Service) Flush()
- func (s *Service) IncidentsCreated(ctx context.Context, actor string, engagementID shared.ID, ...)
- func (s *Service) Notify(ctx context.Context, actor string, a alerting.Alert) Outcome
- func (s *Service) Test(ctx context.Context, actor string) (Outcome, error)
Constants ¶
This section is empty.
Variables ¶
var ErrNoSinkAcknowledged = errors.New("no alert sink acknowledged the test alert")
ErrNoSinkAcknowledged is returned by Test when every configured sink refused the test alert.
Functions ¶
This section is empty.
Types ¶
type Outcome ¶
type Outcome struct {
Matched bool `json:"matched"`
Delivered int `json:"delivered"`
Failed int `json:"failed"`
AuditFailed int `json:"audit_failed,omitempty"`
}
Outcome counts what one notification did across sinks. Matched is false when the rule filtered the alert out; then nothing was attempted.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service evaluates and delivers alerts.
func NewService ¶
func NewService(sinks []ports.AlertSink, rule alerting.Rule, audit ports.AuditLogger, clock ports.Clock, ids ports.IDGenerator) (*Service, error)
NewService validates its dependencies. At least one sink is required: a service with nowhere to deliver is a misconfiguration the composition root should refuse, not a silent no-op.
func (*Service) Close ¶
func (s *Service) Close()
Close stops accepting asynchronous notifications and waits for the queued ones to finish.
func (*Service) Flush ¶
func (s *Service) Flush()
Flush blocks until every notification queued so far has been delivered. Tests use it; a caller in production never waits on delivery.
func (*Service) IncidentsCreated ¶
func (s *Service) IncidentsCreated(ctx context.Context, actor string, engagementID shared.ID, created []incident.Incident)
IncidentsCreated notifies each incident correlation opened. It satisfies correlationuc.IncidentNotifier and returns nothing on purpose: the incidents are recorded, and the per-sink result is in the audit log. Delivery runs on the worker set, detached from the caller's request context, so a slow or dead receiver never holds the agent's ingest; the rate limit and a full queue are audited, never silent.